Healthcare

The attacker didn't guess a password. He called your front desk.

In July, Health-ISAC warned healthcare organizations about a rise in attacks that start with a phone call instead of a hacked password.

1 min readOriginally posted on LinkedIn

In July, Health-ISAC warned healthcare organizations about a rise in attacks that start with a phone call instead of a hacked password.

The playbook is boring, which is why it works. Someone rings your front desk or your IT line sounding rushed and credible. They're locked out. They need a password reset, or the login code sent to a new phone. Ten minutes later they're signed in as your office manager, and everything she can reach, they can reach: scheduling, email, billing, the shared drive.

There's no malware anywhere in that story. Your antivirus has nothing to catch, because the sign-in is real. Somebody was just being helpful.

Two fixes, neither expensive.

First, no password or MFA reset ever happens on the same call. You hang up and call the person back on the number in your employee file. It feels rude for about a week, then it's just how you do it.

Second, get your admin accounts off text-message codes. Microsoft 365 can require a security key or a Windows Hello sign-in instead, and neither of those can be read aloud to a stranger over the phone.

Three days without charts and scheduling costs a practice more than three days of revenue. It costs the calls you never got.

Worth twenty minutes with whoever runs your IT before your next cyber renewal.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions